Does EU AI Act require Transparency & Disclosure?

European Union • phased enforcement

Yes — 2 provisions

Requirements at a glance

This regulation imposes 14 specific requirements for Transparency & Disclosure across 2 provisions:

Transparency Disclosure (Article 50) #

Obligation:
Transparency
phased enforcement
Effective:
Aug 2, 2026
Risk tier:
limited-risk
Scope:
Providers of systems intended to interact directly with natural persons and of systems generating synthetic audio, image, video or text (Article 50(1)-(2)); deployers of emotion recognition or biometric categorisation systems and of systems producing deepfakes (Article 50(3)-(4))
high-impactcross-domain
This is the EU's chatbot and synthetic-media disclosure rule, and it is the provision that lines up against the 2026 US state companion-chatbot statutes. Article 50(1) turns on whether the artificiality would be obvious to a reasonably well-informed, observant and circumspect person, which is the same conditional trigger Oregon and California use and the opposite of Washington's and Colorado's unconditional duty. Unlike Article 13 it sits in Chapter IV, so the Digital Omnibus deferral of Chapter III does not touch it and it applies from 2026-08-02.

Requirements

RequirementDetails
Interaction disclosureProviders must design systems intended to interact directly with natural persons so those persons are informed they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person (Article 50(1))
Synthetic content markingProviders of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format detectable as artificially generated or manipulated (Article 50(2))
Emotion recognition and biometric categorisation noticeDeployers must inform natural persons exposed to emotion recognition or biometric categorisation systems of their operation (Article 50(3))
Deepfake disclosureDeployers generating or manipulating image, audio or video constituting a deepfake must disclose that the content is artificially generated or manipulated (Article 50(4))
Generative AI grace periodPre-existing generative AI systems on the market before 2026-08-02 have until 2026-12-02 to comply with Article 50(2) machine-readable marking (Article 111(4), inserted by Regulation (EU) 2026/1744)
Marking codes of practiceThe Commission facilitates Union-level codes of practice for detection, marking and labelling of AI-generated or manipulated content, assesses their adequacy for Article 50(2) and (4), and may impose common rules by implementing act if a code is inadequate (Article 50(7), as replaced by Regulation (EU) 2026/1744)

Penalties

ViolationFine
Transparency non-compliance (Article 50)Up to EUR 15M or 3% global turnover (Article 99(4))
Incorrect informationUp to EUR 7.5M or 1% global turnover (Article 99(5))
SMC ceilingFor small mid-cap enterprises, each fine under Article 99(4)-(5) is capped at the lower of the percentage or the fixed amount (Article 99(6a), inserted by Regulation (EU) 2026/1744)

High-Risk Transparency and Instructions for Use (Article 13) #

Obligation:
Transparency
enacted
Effective:
Dec 2, 2027
Risk tier:
high-risk
Scope:
Providers of high-risk AI systems. The duty runs to the instructions for use supplied to deployers, not to end users
upcominghigh-impact
Deferred with the rest of Chapter III Sections 1-3 by Regulation (EU) 2026/1744: 2027-12-02 for systems high-risk under Article 6(2) and Annex III, and 2028-08-02 for systems high-risk under Article 6(1) and Annex I. The `Effective` field carries the earlier of the two. While bundled with Article 50 this duty was published as applicable from 2026-08-02, sixteen months early.

Requirements

RequirementDetails
Operational transparencyHigh-risk systems must be designed and developed so their operation is sufficiently transparent to enable deployers to interpret output and use it appropriately (Article 13(1))
Instructions for useHigh-risk systems must be accompanied by instructions for use in an appropriate digital format, containing concise, complete, correct and clear information accessible and comprehensible to deployers (Article 13(2))
Provider identityInstructions must state the identity and contact details of the provider and, where applicable, its authorised representative (Article 13(3)(a))
Capabilities and limitationsInstructions must state intended purpose, the accuracy, robustness and cybersecurity metrics the system was validated against, foreseeable circumstances affecting those levels, and risks arising under intended use or reasonably foreseeable misuse (Article 13(3)(b))
Explainability informationWhere applicable, instructions must describe technical capabilities to provide information explaining the system's output (Article 13(3)(b)(iv))
Human oversight measuresInstructions must describe the human oversight measures built in under Article 14, including technical measures facilitating output interpretation by deployers (Article 13(3)(d))
Pre-determined changesWhere applicable, instructions must describe the changes to the system and its performance which the provider pre-determined at the moment of the initial conformity assessment (Article 13(3)(b)(vii))
Expected lifetime and maintenanceInstructions must state expected lifetime and any necessary maintenance and care measures, including software updates (Article 13(3)(e))

Penalties

ViolationFine
High-risk non-complianceUp to EUR 15M or 3% global turnover (Article 99(4))
Incorrect informationUp to EUR 7.5M or 1% global turnover (Article 99(5))
SMC ceilingFor small mid-cap enterprises, each fine under Article 99(4)-(5) is capped at the lower of the percentage or the fixed amount (Article 99(6a), inserted by Regulation (EU) 2026/1744)
View full regulation View obligation Obligation matrix